Single sign-on for managed mobile devices
First Claim
1. A non-transitory computer-readable medium embodying a program executable in a server computing device, the program, when executed by the server computing device, being configured to cause the server computing device to at least:
- receive a request for an identity assertion from an application executed in a mobile device;
detect that the mobile device is associated with a specific platform of a plurality of platforms;
identify a specific platform adapter corresponding to the specific platform, the specific platform adapter being associated with a type of device management credential, the type of device management credential being a secure certificate or a Kerberos profile;
send, by the specific platform adapter, to the mobile device a response to the request requesting a device management credential corresponding to the type of device management credential, the response further requesting that the mobile device request authentication using the device management credential, the device management credential being used by a device management application that is executed in the mobile device and manages the application;
receive, by the specific platform adapter, the requested authentication request including the device management credential from the mobile device;
determine, by the specific platform adapter, that the device management credential is valid for the identity assertion; and
send the identity assertion to the mobile device in response to determining that the device management credential is valid for the identity assertion.
1 Assignment
0 Petitions
Accused Products
Abstract
Disclosed are various examples for single-sign on by way of managed mobile devices. For example, an identity provider service can receive a request for an identity assertion from an application executed in a client device. The identity provider service can then detect a platform associated with the client device. A response to the request can be sent based at least in part on the platform, where the response requests authentication by a management credential. Data generated by the management credential is received from the client device, and the management credential is determined to be valid for the identity assertion. The identity assertion is then sent to the client device in response to determining that the management credential is valid for the identity assertion.
128 Citations
20 Claims
-
1. A non-transitory computer-readable medium embodying a program executable in a server computing device, the program, when executed by the server computing device, being configured to cause the server computing device to at least:
-
receive a request for an identity assertion from an application executed in a mobile device; detect that the mobile device is associated with a specific platform of a plurality of platforms; identify a specific platform adapter corresponding to the specific platform, the specific platform adapter being associated with a type of device management credential, the type of device management credential being a secure certificate or a Kerberos profile; send, by the specific platform adapter, to the mobile device a response to the request requesting a device management credential corresponding to the type of device management credential, the response further requesting that the mobile device request authentication using the device management credential, the device management credential being used by a device management application that is executed in the mobile device and manages the application; receive, by the specific platform adapter, the requested authentication request including the device management credential from the mobile device; determine, by the specific platform adapter, that the device management credential is valid for the identity assertion; and send the identity assertion to the mobile device in response to determining that the device management credential is valid for the identity assertion. - View Dependent Claims (2, 3, 4, 5, 19)
-
-
6. A system, comprising:
-
at least one computing device; and an identity provider service executable by the at least one computing device, the identity provider service configured to cause the at least one computing device to at least; receive a request for an identity assertion from an application executed in a mobile device, the request including a user-agent string; determine that the application corresponds to a webview of a native application rather than a browser by examining the user-agent string; detect that the mobile device is associated with a specific platform of a plurality of platforms; identify a specific platform adapter corresponding to the specific platform, the specific platform adapter being associated with a type of device management credential, the type of device management credential being a secure certificate or a Kerberos profile; send, by the specific platform adapter, to the mobile device a response to the request requesting a device management credential corresponding to the type of device management credential, the response further requesting that the mobile device request authentication using the device management credential, the device management credential being used by a device management application that is executed in the mobile device and manages the application, the device management credential being a secure certificate or a Kerberos profile; receive, by the specific platform adapter, the requested authentication request including the device management credential from the mobile device; determine, by the specific platform adapter, that the device management credential is valid for the identity assertion; and send the identity assertion to the mobile device in response to determining that the device management credential is valid for the identity assertion. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A method, comprising:
-
receiving a request for an identity assertion from an application executed in a client device; detecting that the client device is associated with a specific platform of a plurality of platforms; identifying a specific platform adapter corresponding to the specific platform, the specific platform adapter being associated with a type of device management credential; sending, by the specific platform adapter, to the client device a response to the request requesting a device management credential corresponding to the type of device management credential, the response further requesting that the client device request authentication using the device management credential, the device management credential being a secure certificate or a Kerberos profile, the device management credential being used by a device management application that is executed in the client device and manages the application; receiving, by the specific platform adapter, the requested authentication request including the device management credential from the client device; determining, by the specific platform adapter, that the device management credential is valid for the identity assertion; and sending the identity assertion to the client device in response to determining that the device management credential is valid for the identity assertion. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 20)
-
Specification